rollback 登录校验

This commit is contained in:
lijiarao
2023-12-06 15:28:47 +08:00
parent 12875c245a
commit 15c2189f07
@@ -1,6 +1,7 @@
package com.jero.modules.system.service.impl; package com.jero.modules.system.service.impl;
import cn.hutool.core.util.RandomUtil; import cn.hutool.core.util.RandomUtil;
import cn.hutool.core.util.StrUtil;
import cn.hutool.crypto.asymmetric.RSA; import cn.hutool.crypto.asymmetric.RSA;
import com.alibaba.fastjson.JSONObject; import com.alibaba.fastjson.JSONObject;
import com.aliyuncs.exceptions.ClientException; import com.aliyuncs.exceptions.ClientException;
@@ -94,22 +95,22 @@ public class LoginServiceImpl implements ILoginService {
String rsaPublicKey = sysLoginModel.getRsaPublicKey(); String rsaPublicKey = sysLoginModel.getRsaPublicKey();
String rsaPrivateKey = redisUtil.get(rsaPublicKey) != null ? String.valueOf(redisUtil.get(rsaPublicKey)) : null; String rsaPrivateKey = redisUtil.get(rsaPublicKey) != null ? String.valueOf(redisUtil.get(rsaPublicKey)) : null;
//if(StrUtil.isEmpty(rsaPrivateKey)){ if(StrUtil.isEmpty(rsaPrivateKey)){
// return Result.error(CommonConstant.SC_RSA_TIMEOUT_600, "页面过期,将刷新页面"); return Result.error(CommonConstant.SC_RSA_TIMEOUT_600, "页面过期,将刷新页面");
//} }
//String captcha = sysLoginModel.getCaptcha(); String captcha = sysLoginModel.getCaptcha();
//if(captcha==null){ if(captcha==null){
// return Result.error("验证码无效"); return Result.error("验证码无效");
//} }
//String lowerCaseCaptcha = captcha.toLowerCase(); String lowerCaseCaptcha = captcha.toLowerCase();
//String realKey = MD5Util.MD5Encode(lowerCaseCaptcha + sysLoginModel.getCheckKey(), UTF_8); String realKey = MD5Util.MD5Encode(lowerCaseCaptcha + sysLoginModel.getCheckKey(), UTF_8);
//Object checkCode = redisUtil.get(realKey); Object checkCode = redisUtil.get(realKey);
//// 验证码前后端比较 // 验证码前后端比较
//if(checkCode == null || !checkCode.toString().equals(lowerCaseCaptcha)) { if(checkCode == null || !checkCode.toString().equals(lowerCaseCaptcha)) {
// return Result.error("验证码错误"); return Result.error("验证码错误");
//} }
//redisUtil.del(realKey); redisUtil.del(realKey);
try { try {
//解密获取密码和用户名 //解密获取密码和用户名
password = CommonUtils.decryptBtRsaPriKey(password, rsaPrivateKey); password = CommonUtils.decryptBtRsaPriKey(password, rsaPrivateKey);
@@ -138,15 +139,15 @@ public class LoginServiceImpl implements ILoginService {
return Result.error("密码错误次数过多,请15分钟后重试"); return Result.error("密码错误次数过多,请15分钟后重试");
} }
//2. 校验用户名或密码是否正确 //2. 校验用户名或密码是否正确
//String userpassword = PasswordUtil.encrypt(username, password, sysUser.getSalt()); String userpassword = PasswordUtil.encrypt(username, password, sysUser.getSalt());
//String syspassword = sysUser.getPassword(); String syspassword = sysUser.getPassword();
//if (!syspassword.equals(userpassword)) { if (!syspassword.equals(userpassword)) {
// // 重试登录次数加一 // 重试登录次数加一
// retryCount++; retryCount++;
// this.setRetryInfoToRedis(username, retryCount); this.setRetryInfoToRedis(username, retryCount);
// String msg = retryCount == RETRY_LOGIN_MAX_COUNT ? "密码错误次数过多,请稍后重试":"用户名或密码错误,剩余可登录次数:"+(RETRY_LOGIN_MAX_COUNT - retryCount); String msg = retryCount == RETRY_LOGIN_MAX_COUNT ? "密码错误次数过多,请稍后重试":"用户名或密码错误,剩余可登录次数:"+(RETRY_LOGIN_MAX_COUNT - retryCount);
// return Result.error(msg); return Result.error(msg);
//} }
//登录成功,清除错误登录次数 //登录成功,清除错误登录次数
redisUtil.del(RETRY_LOGIN_PREFIX + username); redisUtil.del(RETRY_LOGIN_PREFIX + username);
if (checkSysPermission(username)) { if (checkSysPermission(username)) {